-
Type:
Bug
-
Resolution: Unresolved
-
Priority:
Medium
-
None
-
Affects Version/s: 11.13.1
-
Component/s: Features - Grid
-
1
-
Severity 3 - Minor
-
No
Issue Summary
When accessing the Recycle/Cancel bin, user can select "All Programs" to display the items that were deleted/canceled, even the ones he is not part of the Portfolio/Program. Due to this, he is able to restore/delete items that he normally is not able to see on the grids.
Steps to Reproduce
- Under Settings > Roles > Select a Role > Expand 'Solution' disable all capabilities permission
- Under Settings > Roles > Select a Role > Expand 'Team' disable all defects permission
- Navigate to the Home page and click on the Items dropdown, notice that the user doesn’t have access/view of Capabilities and defects
- Access the recycle bin under Stories/Features > More actions
- Notice that all the item dropdown shows Capabilities and Defects and the items under it are visible and deletable/restorable for the user
- Notice that for some users, they can see items from other programs/portfolios/users
Expected Results
Recycle/Cancel bin would follow the same logic that the grids use for access to items.
Actual Results
Recycle/Cancel bin doesn't apply the logic of being a member of a Portfolio/Program/Have toggle permissions to see items.
Workaround
Currently, there is no known workaround for this behavior. A workaround will be added here when available